﻿using System;
using System.Collections.Generic;
using System.Linq;
using System.Web;
using System.Data.SqlClient;
namespace WebApplication1
{
    public class DBconnection
    {
        public void insertUser(User user)
        {
            string Commandtext = "insert into Users (Name,Email,Grade,Subject,Files,PaymentType,CardName,CardNumber,ExpiryMonth,ExpiryYear,CCV) Values('" + user.Name + "','" + user.Email + "','" + user.Grade + "','" + user.Subject + "','" + user.Files + "','" + user.PaymentType + "','" + user.CardName + "','" + user.CardNumber + "','" + user.ExpiryMonth + "','" + user.ExpiryYear + "','" + user.CCV + "');";
            string connectionString = null;
            System.Configuration.ConnectionStringSettings connString = System.Configuration.ConfigurationManager.ConnectionStrings["BeyondStudyConnectionString"];
            connectionString = connString.ConnectionString;
            SqlConnection connection = null;
            connection = new SqlConnection(connectionString);
            connection.Open();
            SqlCommand command;
            command = connection.CreateCommand();
            command.CommandText = Commandtext;
            command.ExecuteNonQuery();
            connection.Close();
        }
    }
}
